From 34de0252e54ce0f5243b351281af3fe0b15e0a16 Mon Sep 17 00:00:00 2001 From: Sander Roosendaal Date: Tue, 16 Jul 2024 10:08:17 +0200 Subject: [PATCH] added js logging --- rowers/tests/testdata/testdata.tcx.gz | Bin 3999 -> 4000 bytes rowers/urls.py | 1 + rowers/views/apiviews.py | 56 +++++++++++++++++++++++++- rowers/views/workoutviews.py | 2 +- rowsandall_app/settings.py | 5 +++ 5 files changed, 61 insertions(+), 3 deletions(-) diff --git a/rowers/tests/testdata/testdata.tcx.gz b/rowers/tests/testdata/testdata.tcx.gz index 4c96e43b7a62f417ab87b7e4282417281b4d5c6b..cd7ae246ebbbaef71974d7a756e85979ee49c3e4 100644 GIT binary patch delta 3914 zcmV-Q54G^0AD|xxABzYGyC;^B2OkrPnscdB7sogvkkujq8wHfj+p3W{BYz*?ou2Hy zSzc^bXY2cS(ZJok9}n*wytwFA>(%=B;d0$CFCKM$_eZx`?xmgAoBMZP_5Jz&V)6Fv zTXWo9oUYd9=4K?&hVDa*~RgK0C4g9(-kMrx2L$bT5tMpeY8wRZC3lc^FBF|@D~BtlL!GZe?LFF z=ad-D+`ug$9LjrX7K<*K|K;E~wPtHU~9N}*O`v3=vwA07^pLFMY&-?D8 zf3Z4U-oN`-$6j729s1&|?@sbz&zDDM>zA8DVSljrYU`&19<6q7(9>o5v72Fd+~(+!Bb<_500#Feif zueYyi|Ne0MRxA_Q%Pm(QI^1HyI2KvWP{Vdf1V$7Mcm0%#63Yoa6!SHlHOF1d$>7ws!QIjRK(pGVpNUt zX^7y0+~aJxJ6jR=nB?7x*Km&|<(*+R+cdn!v$21@Az8>xZ#s{<-dG}&ue#V@M0`!&(Ddx4Hc13dO8!T zlCL0^jM7<}(P)nqk&h-Ic&kdgYvgA@p2@g~QAIu{=N2SCe&bJ@ zy=6escyiKy5_eZg}fMG2r8KuDjKnAk3yaeTNKqiAGoN7=bOxrLf#pSC@Ptcf3~Riw#ocBYG9Q{%Hwt-gD5BGNZ!No``SziW z_G6G|*tW#d==RpSqPl%(@%d56lW`1D)dWw2j)2BgCRs!=LCsmYixYe?Z+UGU?LK0ytfXp<=#$T=8=sAB2ARm;dIDz z^W+SYcRA}?)d|rN7S-+NM82lcJ{mv_n)tk9Dq2PDTYP>D@;Uc5V9@lvb(V_e-p+}9 ze?|5@Swjw4HO~u8Cij+G{rn(#Z_pyCMtes^?fDszcT^Gi+&O_*)8F2CE;`T8iF`%6 zebUxAqH5JL7q~@fXFy&IfT+5hyT~m{JN?m~y%EuMLiEtc-;{hsy1fO%UR0hOkG7RHLWtBAZe2m~6dE?}69%s2AGpF03GJiwz zu_E$fASg$BTXdzuS$T3Q8tu^=FQV#}5?s;MN$2Ff^;8deg4`R6HJ+SMc8yA*Mt&6X zY>;$4FheN1YT2B~*EG+Qm>?K6e;Jq|V$sYDn$bM(D1h-J%d=7gRrLLak+A9Ye+cGbd$ejN0<6RKlXW)`Lyt7-T%e?TvJz*mKA5rv9I z>*u8ARb@F(U$hVItuiv98Fz!|tpOm`Nqw-B zL66P28$|CDdR-HZoXu4fJva2DppPb6rAvpv6*catdGp3VpOp28y0ROj?D%g|KY8?G zoY$hKvaQnQB=t}cfBIlVNYwxvDOrTRp`W%($LG$N)`_T$J4y$M9&7Du4@)j zEV^*%tOk6l2)#34Ntcn!z>`_yrp@)k=!1!(tiEBiMO`{=f36<|J)wz2pi0nUn$DVL z&4)jX-kQM5>KkS^nWkwiOJ^9pH{J@XG<>#Y*SVoqb2kS1oM9=btFLD%+fId=nl}o1 zHUb!RQt!fK27GJ@T7&4Fv8Y?i5ZT9~jnk;v^`oGVh9X*>h9Am?Z@78$#z1c=_s`OK z^Ek$)=1qUVf45>ll!aFoVKVXh+LEy=3fkJFu_48%LQmA@`st$=Fj2X1FA@`cM)2kUMDUf4XYeST=maZNMJ`J)&V2r;>Vs zvdh);jMO}+2)*65R#2&VQn-!Moa*asMd-aDs|?x-Ls4&@Z3F%o=m`uGBdgF`n9SOS z&6_ujep_Tss(5{}2wIW#45Z%Wt{PE?-ceEGu65NI2Ytv=?{x#d=gCNY8}J9wGnyc* zi`PrAe?>L?7PK7)y)_OIRb4eC+UCuhz9W~t@k~|~v~}Pnld93wyg~HIPO}bmSvn3~ z8}O%|o0rhD5z0;)4SJeR2}Wz9G>qOE3pvqJgPubh@Tc#{wK1V5QWah~8z)m~+p=^9 z(F+;Y`tY5DHrLMpy%-{`n&+WqYW1vUM z4ONs<&t*$6papG5K`*(X3hAWYO3}z2G&OG&^ue%T&`G_xqNy59%^L+hCF72itrfg; zf6b9Qb(c=eEfYbzrmgpWGIKq(pzR>~Tx89l3g7tPn_WKx^wCJN?sQTg{bcNVYHHpP zdL|>*>cTexLbK~<1e|`k?&Um&_<pvuw-p=hP;tB9#r=LYwPHLGN?*e~l77 z`^l_s+2;B|^m!#~MpAk6qV+|qZ>aUn8wEXY7co~EcTr+n-E!jIyo}!E!Yd_u7mG@L zYm_<;`j`u^bas6V(3+=B+?$usZ&$KbM($$7)){*S=&eaJy=nmz0%$#QZ;IZJh5p0V zj~fmaPrCEV56{l}<>v6alm3UFe@~XD%XPo^{dUv$dtJW=@BE*Cde;%fH1U6T-2ZT} z*d1_ZcczcOF@L`NwAy`t@bDsWJiGX?@3StwJr`$hH{JSWcXG0QTIu6zef+ZPyL8@e z_jV;JpN>0t@Vb9>c5&r3d2oJyvO4Pe^wTe2jLUO>b+Yu`Pp?-eFE4-Ye{bo1Oov{1 zI3Kn=?f#Q4nVkh!KYzX3YMnNF`Ly45!{wv>;`|3M(oG-!x;$BSn`PpVKYe&~SMKZJ zNw+?J{OIuKXPM3R&)xQ4(p&uO_30nWbY}qf0CxW$EUtX9d-B`Iba-crdbLi^;bB6# Yym*wJ#vkd@hj;!5(b%r91jK*=03!zV_5c6? delta 3913 zcmV-P54P~2ADNE{<_TAge_JHVP=4w^fljBY&UXou2Hy zSzc^bXX|@+(ZJokpAPRFJiq8x>(%=B!E)U%FCKP%_oCY@_tMVm&Aq#?`u==>v3UFT ztvT*4PFHJlbauK(Uv7?GEl<16;`+lEZ|Lss6#Lz~Z#c{Sqki>f)xZDcUB6uC8@zIY zcbnB`XL!rz?BaMq0J!+$$ra;g+f)3oT5tMpeY8wRZC3lc^FBV2@D~BllL!GZe>*?B z=ad-D+`ufq!LjrU^fc!x49C_d3J~;oJu(oP@uf83q#J?p!R z{`u;3dGGFD9ea79bm;T5zB|c>JzE}~tzT{qh5fB#^LuyldU=R8U1ay?rz{@{Pd6a$nj5(05?8){ zwBEj|{rki1Td_=JFSlHMkS~|%0Ur|P$GH3Z3dM`n@o~DfW&i5z<>8ZVfBm{UNfbZZ zdUfya=)a%c{dUXw*=pTi-JHKj@4z>_i`(5kKk|!LLW~`LO|}QzlE768%q55%&ZU!370(N_ta4?&0R#sV;f9QW1A&h*34l zry+t1a*wm&?rcTeW0H3(Uc)_>ly`>NaQ78)x3nGSor1d!h6-}WTX4s!xCf|+yCm*O zs5IKVH*O-_>yr1t6>;|_cyJnh-no)y9MgQb`+B$w7$4AT`1DXP!UN8S-CQtTueW}TZBp)7g61$nBAJXJHr(>^3q zPIRUmqLlRAu$_<0vs6UhnwXS&mCTcvP>{ULhFG?U zO1^?vGD>G@Mx#AeL_V5;;H@g{u92Ssc_!l`Miu#-oLi9me~kS0HI4Qxh8=j#JWsYP zc{?NW6-8_~7y$61AumueI&W{|x94Wn4UtdsYaOc6ut;J_AKt9USLDO9Y#7mMqO|0T zX4p6KBawFotde|y$;fzdzw6!Kz#A*f_tsA$BdkspV=Hz7$pYREfoGJiwzTn~8!BLRY{ zNrva5GVhyiKMHv^Y*AG6eBh!Qo^LWg3VCNRqNrp(f7+tn+a~klkl*Iss#>7gvK5uL zB9G07H$*6-6-U}p@>f7y|wI$=G%uh z+K)k=VcQZ*quX2Sit6^E#pg#MPsTAsRTDfZOMXrjm98T4VyrN$=6P4NmUdR;r6Tgd zB<`vVe@t7pqEevA{21gdnxt_$QnfrS+Ur(kR7EYeBJym!(?w}*j3sk&=0v`p8XL~J zx6UJKMteb+jLbKCewchT6d(o_`Pg*(=|^mYa<>#!lvWs;Za;mQ7i&V&?Nu^w%Vu52 zR!chyd2fVu5gU=RsnkRe}7Z*wj%Omg4b17iO0#r=bOwAlNVzN zRn=7z%GTAj9+=~h4~7s`of9OMt+DY$f=dpjrc ze-+vDWDPlF)jTgWncQ1$_49+|y+Mnl8tokwwdZF<-cd#5bLRwNO@Djmx#&DUC-N2P z_DNggh^ke~T;LX^odJ0<0HW%0?jpA+?es@`_C`e43DH9%e^c@m>Gl>3dr^6EJlc{P z-mUWRnua$_o^$t8mG{;sOE9(!%*m4%f8(t~O{~r*-JoEsPH;x{d`0nj8;nIpO-_za zZ;PD>`PzJVp&s&rxt3P7riGWH_49L*`IAKYYg`{unJATRrX#w&ezJ{Dbtd{#0q6_K~bf~aIZe?ZZ- zsAnbft|Ic@AP{J*x`1IaGT+D#laI!w!Co`k2MR^)`8kdDp&s%`##)S;tn0wB$@~q; z$BM{{fuJ1iZPAqqXXVMMXtYOfyojn>N^nJ2C!Le`)>A#?336{N)_8J4*)=MK8u?Mk zvq94Jzzm`2s%3K`U(-BKVuE1Qe`H{Wh($9qXh!qAuZVmwl4M>}X%T^%%uhX5C;N=X zGO02%B61@?^@vR(Zw;k?D)Llx9h+Q#+A=dnAn$V?o~j>Sd(a~klmBJ`Z*dIHs4j}RtdJ1Avg5x={p8V$ zabAm_%C<_Ilhi{+f9Qh|Ayorxq+}8LhJM;E9iKa6S|_41?kFh;GLiN<*p{UqL~jjy zUHhE8Fves$CpEi%7`->v8j1upvNS@%7QzjfRpKni!Cj45Iq}ox~^GB zvFO63vl{TJBJ|FHC0#}?15aj+n>N=EqYoyEvigS67Io>gf4P1X^n@l7fhs|ZX*z3~ zH6Q*kdTRnJt8bXyWSXY6ES+KW-gqml((u`qUFU{c&D|L2bB3j$uD+h7Y&#WdYThX5 z*$80NNxch`8St?sXbqxw#-eU5Lu4O|Hcq2v*N=ie8j5Ij8h$7nzTxK08w0(i+&@d_ z&EpuGnm7Fcf8UA$Q5IfVgvrF~YfHwiC}?Yw#)cH53O!Mq>!*)iz(nQ3#b}v|M(&yq ze;o8|qC?W5w>+8U&6*>382z?oqF1STR%~bm6`}WrtTJdT3`M9P}Yez1I!+o+l&qZNMKy&uD_M zE?zIee-_p7ThMkK^wu~;RCU#mXqz{0`i@-o#xq$}(AI&QOsYmx^9Io;JIy-OW$8F{ zZNQ&;ZeBvqMkqUJH0WtMB^a%Z(lB~wEaXH>4SEi3z@NS&*T#gNNL6^{Y@AG`ZOhUb zL@#7m>%(^r+FU;a^kRs#YMzIdkvsLmtB_kJe`4CELmzN54ON<&H-J9omWhBEb#{HE zmXF$$)Ll9;w@d`>nzr8i$;|cCg0_R`bCETJDtzOEZ+86*&_^T5y3Y0> z>?gCjWt-~<(dU({8A;{Mi`EydzM{hac^Eizg@{%8M%uQTW9PUptmN?^r{6=2%z=Iy(xM>7Wxlc zKW;c!JnqgfKRi9_mz%@yPWm5ze>qv6F4z6u_uEb1?{)niyz_r{j)=PMMS$;)`yUS$ zy94g*&h+s&=FgX(R=e*H9$X}jXBQv#ecGkB=i=<`rdz-4PENK@D}7w8k6(6um(JVm z-mXOD({Ts)U-z%hF0Q;L_s`EyR!3c*e){E$ae3~qPL{s=`St4L<>k-)e?7gA>Ch_= z=fjpK-G9<0v$Npp=dX8LtNpZ42sxO}u) X7Z20Zc#$rBc;|n5kfmP41AqYlc`o7A diff --git a/rowers/urls.py b/rowers/urls.py index 34fdc057..6f07085a 100644 --- a/rowers/urls.py +++ b/rowers/urls.py @@ -240,6 +240,7 @@ urlpatterns = [ # re_path(r'^oauth2/', include('provider.oauth2.urls', namespace = 'oauth2')), # re_path(r'^o/authorize/$', base.AuthorizationView.as_view(), name="authorize"), # re_path(r'^o/token/$', base.TokenView.as_view(), name="token"), + re_path('^log/$', views.javascript_log), re_path('^o/', include('oauth2_provider.urls', namespace='oauth2_provider')), re_path(r'^', include(router.urls)), re_path(r'^api-docs/$', views.schema_view, name='schema_view'), diff --git a/rowers/views/apiviews.py b/rowers/views/apiviews.py index bba37957..5ef9c3a3 100644 --- a/rowers/views/apiviews.py +++ b/rowers/views/apiviews.py @@ -6,6 +6,7 @@ from xml.etree import ElementTree as ET import arrow import pendulum +from pendulum.parsing.exceptions import ParserError from rowsandall_app.settings import UPLOAD_SERVICE_SECRET, UPLOAD_SERVICE_URL from rowers.dataroutines import get_workouttype_from_tcx, get_startdate_time_zone @@ -34,7 +35,51 @@ class XMLParser(BaseParser): # Stroke data form to test API upload +@csrf_exempt +def javascript_log(request): + if request.method != 'POST': + message = {'status': 'false', + 'message': 'this view cannot be accessed through GET'} + return JSONResponse(status=403, data=message) + # test if JSON + try: + json_data = json.loads(request.body) + secret = json_data['secret'] + post_data = json_data + except: + q = request.POST + post_data = {k: q.getlist(k) if len( + q.getlist(k)) > 1 else v for k, v in q.items()} + + # only allow local host + hostt = request.get_host().split(':') + if hostt[0] not in ['localhost', '127.0.0.1', 'dev.rowsandall.com', 'rowsandall.com']: + message = {'status': 'false', + 'message': 'permission denied for host '+hostt[0]} + return JSONResponse(status=403, data=message) + + # check credentials here + try: + secret = post_data['secret'] + except KeyError: + dologging('own_api.log','Missing credentials') + message = {'status': 'false', 'message': 'missing credentials'} + return JSONResponse(status=400, data=message) + if secret != settings.LOG_SECRET: + message = {'status': 'false', 'message': 'invalid credentials'} + return JSONResponse(status=403, data=message) + + try: + message = post_data['message'] + except KeyError: + dologging('javascript_log.log','no message received') + message = {'status': 'false', 'message': 'no filename given'} + return JSONResponse(status=400, data=message) + + dologging('javascript_log.log', message) + return JSONResponse(status=200, data = {'status': 'true', 'message': message}) + @login_required() @permission_required('rower.is_not_freecoach', fn=get_user_by_userid, raise_exception=True) def strokedataform(request, id=0): @@ -547,7 +592,10 @@ def strokedatajson_v3(request): rpe = request.data.get('rpe',0) startdatetime = request.data.get('startdatetime',"%s" % timezone.now()) - startdatetime = pendulum.parse(startdatetime) + try: + startdatetime = pendulum.parse(startdatetime) + except ParserError: + startdatetime = timezone.now() dologging('apilog.log',workouttype) dologging('apilog.log',boattype) @@ -570,7 +618,11 @@ def strokedatajson_v3(request): except: return HttpResponse("No JSON Object could be decoded", status=400) - df = df.sort("time") + try: + df = df.sort("time") + except ColumnNotFoundError: + return HttpResponse("No time column", status=400) + status, comment, data = api_get_dataframe(startdatetime, df) if status != 200: # pragma: no cover diff --git a/rowers/views/workoutviews.py b/rowers/views/workoutviews.py index 9b3d92fe..70839e7e 100644 --- a/rowers/views/workoutviews.py +++ b/rowers/views/workoutviews.py @@ -4819,7 +4819,7 @@ def workout_toggle_ranking(request, id=0): @csrf_exempt def workout_upload_api(request): - if request.method!= 'POST': # pragma: no cover + if request.method != 'POST': # pragma: no cover message = {'status': 'false', 'message': 'this view cannot be accessed through GET'} return JSONResponse(status=403, data=message) diff --git a/rowsandall_app/settings.py b/rowsandall_app/settings.py index 3f0be6be..8c1d4255 100644 --- a/rowsandall_app/settings.py +++ b/rowsandall_app/settings.py @@ -283,6 +283,11 @@ try: except KeyError: # pragma: no cover UPLOAD_SERVICE_SECRET = "FoYezZWLSyfAVimumpHEeYsJjsNCerxV" +try: + LOG_SECRET = CFG['log_secret'] +except KeyError: + LOG_SECRET = "RoeiKalender" + # Concept 2 C2_CLIENT_ID = CFG['c2_client_id'] C2_CLIENT_SECRET = CFG['c2_client_secret']